Introduction
SpellTrack is a spelling practice app designed for UK primary school children, managed entirely by their parents or guardians. Your privacy and your child's privacy are extremely important to us.
This policy explains what information SpellTrack collects, how it is used, and the choices you have. It is written in line with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the Age Appropriate Design Code (AADC).
Data Controller
The data controller responsible for your information is:
Anas Imtiaz
Email: hello@spelltrack.app
What We Collect
Account Information
- Email address — used to create and sign in to your account
- Password — stored as an irreversible encrypted hash; we cannot see your password
Child Profiles
Parents create simple profiles to organise spelling practice. Each profile contains:
- A first name (or nickname) chosen by the parent
- A year group (e.g. Year 3, Year 5)
- An avatar selection
Important: Children never create accounts or interact with SpellTrack unsupervised online. All profile information is entered and managed by the parent. We only store the first name or label you choose — no surname, date of birth, photographs, or other identifying details are collected.
Learning Data
- Spelling lists — words assigned to your child's group
- Practice results — scores, session history, and progress over time
- Words needing extra practice — flagged automatically or by a parent
App Security
- Parental password — an optional PIN or password to prevent children from accessing settings; stored as an irreversible hash
How We Use Your Data
We use the information we collect solely to provide the SpellTrack service:
- Authenticating your account and keeping it secure
- Displaying the correct spelling lists for your child's year group
- Tracking practice progress so you and your child can see improvement
- Syncing data across your devices so you can use SpellTrack on any iPhone
We do not use your data for advertising, marketing, profiling, or any purpose beyond delivering the app's core functionality.
Legal Basis
Under UK GDPR, we process your data on the following grounds:
- Contract performance — processing your account and learning data is necessary to provide the service you signed up for
- Legitimate interest — keeping the app secure and functional
- Parental consent — child profile information is provided voluntarily by the parent or guardian, who maintains full control over it at all times
Data Storage & Security
- Account and learning data are stored securely using Supabase, a cloud database platform with encryption at rest and in transit
- Spelling lists and practice data are also cached locally on your device for offline access
- Passwords and parental PINs are stored as one-way cryptographic hashes — they cannot be reversed or read by anyone, including us
- The parental password is additionally stored in the iOS Keychain, Apple's secure on-device storage
Third-Party Services
SpellTrack uses the following third-party service:
- Supabase — for secure authentication and cloud data storage
We do not use any analytics, advertising, or tracking services. No data is shared with or sold to third parties. SpellTrack contains no ads.
Children's Privacy
SpellTrack is designed with children's safety as a priority, in line with the UK Age Appropriate Design Code:
- Children do not create accounts — only parents or guardians can register
- Children cannot share data, contact other users, or access the internet through the app
- Child profiles contain only a first name or nickname, year group, and an avatar — no sensitive personal information
- An optional parental password prevents children from changing settings
- All data is fully controlled by the parent, who can edit or delete it at any time
Your Rights
Under UK GDPR, you have the right to:
- Access the personal data we hold about you
- Correct any inaccurate information (you can edit child profiles and account details directly in the app)
- Delete your data — use the "Reset All Data" option in Settings to remove all data from our servers and your device, or contact us to request full account deletion
- Data portability — request a copy of your data in a portable format
- Object to processing or restrict how your data is used
- Lodge a complaint with the Information Commissioner's Office (ICO) if you believe your rights have been infringed
To exercise any of these rights, email us at hello@spelltrack.app.
Data Retention
We retain your data for as long as your account is active. If you choose to delete your data:
- Reset All Data (in app Settings) removes all learning data, child profiles, and school information from both your device and our servers immediately
- Account deletion can be requested by emailing us; we will delete your account and all associated data within 30 days
We do not retain any personal data after deletion, except where required by law.
Changes to This Policy
We may update this privacy policy from time to time. If we make significant changes, we will notify you through the app or by email. The date at the top of this page shows when the policy was last updated.
Contact Us
If you have any questions about this privacy policy or how SpellTrack handles your data, please contact us:
Email: hello@spelltrack.app